criticalCVSS 9.9Vulnerability
CVE-2026-49252
### Impact Prototype pollution in deepstream server v <=10.0.4. Potential privilege escalation from any authenticated user with write permission to any record. ### Patches Yes, upgrade to v10.0.5 ### Workarounds Filter out all messages containing the path `__proto__`, `constructor`, `prototype`, **before they reach the server's message pipeline**
Properties
- severity
- critical
- summary
- deepstream is vulnerable to prototype pollution
- epss_score
- 0.0047
- cvss_score
- 9.9
- ghsa_published
- 2026-06-26T21:03:59Z
- source_url
- https://github.com/advisories/GHSA-9v98-6g37-x9g6
- ghsa_updated
- 2026-06-26T21:04:00Z
- ghsa_id
- GHSA-9v98-6g37-x9g6
- cve_id
- CVE-2026-49252
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
- is_ghsa_only
- false
- epss_percentile
- 0.38253
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/@deepstream/server
AFFECTS (1)
→[Software]npm/@deepstream/server
HAS_WEAKNESS (1)
→[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Explore deeper with Ninja Signal's threat intelligence graph